VULNERABILITY INTELLIGENCE
CVE-2010-2807
CVSS score6.8 MEDIUM
EPSS probability4.20%
CISA KEVNot currently listed
Published2010-08-19
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Description
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Weakness classification
- CWE-681: Incorrect Conversion between Numeric Types
Primary references
- secalert@redhat.com — Release Notes, Third Party Advisory
- secalert@redhat.com — Patch, Third Party Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Mailing List, Patch, Third Party Advisory
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Product, Third Party Advisory
- secalert@redhat.com — Broken Link
- secalert@redhat.com — Third Party Advisory